What is local login?
When SSO is enabled in your organization, your users sign in to LockSelf through your identity provider (IdP) — Microsoft Entra ID, Okta, Google Workspace… — and then enter their master password to access their space.
Local login allows an SSO user to sign in to LockSelf without going through the IdP, using only their email address and master password (plus their two-factor authentication code if it is configured).
No additional password needs to be created: the user signs in with the same master password as usual.
When should you enable it?
- Emergency access: make sure one or more accounts (for example an administrator) can always access LockSelf if your IdP is unavailable.
- User temporarily blocked on the IdP side: let a user keep accessing their passwords while an issue with their directory account is being resolved.
Good to know before enabling it
- Local login is disabled by default and is enabled user by user.
- It does not rely on your IdP's controls (strong authentication, conditional access rules…): reserve it for accounts that really need it and enable LockSelf two-factor authentication for these accounts.
- Your organization's login rules (time slots, IP ranges, manual blocking…) still apply.
- Without local login, an SSO user can only sign in through the IdP: if they try to sign in another way, a message tells them that their organization's settings do not allow it.
Who can enable local login?
Super Admins, Admins and Moderators, from Management.
The option is only available for SSO users: the toggle does not appear for a standard user, who already signs in with their email address and master password.
Enable local login
To allow an SSO user to sign in locally:
- In Management, click the relevant user to open their panel.
- Open the "Settings" tab.
- Turn on the "Local login" toggle.
A "Local" badge then appears next to the user in the Management list, so you can see at a glance which SSO users are allowed to sign in locally.
Disable local login
- In Management, click the relevant user.
- Open the "Settings" tab.
- Turn off the "Local login" toggle.
The user can then only sign in via SSO, through your IdP.
Sign in locally
Once local login has been enabled by their administrator, the user signs in from the usual LockSelf login screen:
- Enter your email address.
- If two-factor authentication is configured, enter your MFA code.
- Enter your master password and confirm.
To learn more about the master password (and how to reset it), see the article The master password.
What has changed compared to local passwords
- You no longer need to create a separate local password for an SSO user: you now simply allow local login for them.
- The "security key" is now called the "master password". It is the one used for local login.
Updated